FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tana
Staff
Staff
Article Id 425599
Description

This article describes the steps to troubleshoot intermittent connection issues with FortiClient EMS.

The issue occurs when an error is shown on the Fabric connector for EMS, showing the error: 'Connection failed with unknown issue' message.

 

error.jpg

 

Even though the FortiGates have connectivity between both devices and it restores automatically within a few moments.

Scope

FortiGate versions 7.4.8 and 7.4.9.

FortiClient EMS Cloud version 7.4.3.

Solution

To troubleshoot intermittent connection issues with FortiClient EMS, follow these steps:

  • Check the FortiClient EMS version and ensure it is compatible with the FortiGate version. In this case, the FortiClient EMS Cloud version is 7.4.3.

 

  • Verify the connectivity between the FortiGate and FortiClient EMS by running the command diagnose endpoint fctems test-connectivity 2. If the connection test is successful, proceed to the next step.

 

 

  • Run the CLI commands to check the FortiClient EMS context status : 

 

diagnose endpoint fctems test-connectivity 2
diagnose endpoint fctems test-authorization 2
diagnose endpoint filter show-large-data yes
diagnose test application fcnacd 2

 

  • If, for some reason, the certificate is shown as not authorized, the certificate authorization may be executed via CLI with the command below:

 

execute fctems verify 1

 

  • When it happens again, capture fcnacd debug logs by running the commands below: 

 

diagnose debug console time enable
diagnose debug application fcnacd -1 <--- Capture output about 2-3 mins.

diagnose debug enable

 

  • Once the issue has finished occurring, save the output logs and upload them to the support ticket with Fortinet TAC Support for further analysis.

 

Note: The engineering team has identified this issue as a known bug (bug id: 1207648) and is working on a fix, which is scheduled to be released in FortiOS v7.4.10.

 

Related articles:

Troubleshooting Tip: FortiGate to FortiClient EMS connection error: 'Connection failed with unknown ... 

Troubleshooting Tip: FortiGate cannot connect to EMS cloud using PPPoE internet and after the firmwa...